Abstract
Purpose: This paper aims to provide: (a) an outline and description of cognitive dissonance theory; (b) an overview of cognitive dissonance interventions; (c) a high-level view of cognitive dissonance theory (CDT) research; (d) a review of existing mentions of cognitive dissonance, and studies meaningfully applying CDT to cybersecurity; (e) suggestions for future research.
Design/Methodology: We conducted a general review of cognitivedissonance research and three literature reviews of: (a) cognitive dissonance at a high level, (b) cognitive-dissonance interventions and (c) cognitive dissonance in cybersecurity.
Findings: Cognitive-dissonance theory is compact and widely applicable. Cognitive-dissonance theory paradigms provide a basis for interventions across domains. Awareness of cognitive dissonance is relatively widespread in the cybersecurity literature. Many publications mentioned cognitive dissonance in passing. However, less than 13% of publications meaningfully focused on cognitive dissonance.
Research Implications: Cognitive-dissonance theory provides concepts and techniques to develop further insight into the cybersecurity attitudebehaviour gap. These have the potential to help bridge the gap and thereby increase cybersecure behaviour. Such interventions should be designed and evaluated in future research.
Originality: This paper makes an original contribution to cybersecurity research by identifying: (a) cognitive-dissonance paradigms that form the potential basis for interventions to increase cybersecure behaviour, (b) cybersecurity areas that potentially benefit from such interventions and other areas in which cognitive-dissonance theory has been meaningfully applied; (c) directions for future research, most notably focusing on how to apply cognitive-dissonance-based interventions.
Design/Methodology: We conducted a general review of cognitivedissonance research and three literature reviews of: (a) cognitive dissonance at a high level, (b) cognitive-dissonance interventions and (c) cognitive dissonance in cybersecurity.
Findings: Cognitive-dissonance theory is compact and widely applicable. Cognitive-dissonance theory paradigms provide a basis for interventions across domains. Awareness of cognitive dissonance is relatively widespread in the cybersecurity literature. Many publications mentioned cognitive dissonance in passing. However, less than 13% of publications meaningfully focused on cognitive dissonance.
Research Implications: Cognitive-dissonance theory provides concepts and techniques to develop further insight into the cybersecurity attitudebehaviour gap. These have the potential to help bridge the gap and thereby increase cybersecure behaviour. Such interventions should be designed and evaluated in future research.
Originality: This paper makes an original contribution to cybersecurity research by identifying: (a) cognitive-dissonance paradigms that form the potential basis for interventions to increase cybersecure behaviour, (b) cybersecurity areas that potentially benefit from such interventions and other areas in which cognitive-dissonance theory has been meaningfully applied; (c) directions for future research, most notably focusing on how to apply cognitive-dissonance-based interventions.
| Original language | English |
|---|---|
| Number of pages | 29 |
| Journal | Information and Computer Security |
| Early online date | 1 Jun 2026 |
| DOIs | |
| Publication status | E-pub ahead of print - 1 Jun 2026 |
Fingerprint
Dive into the research topics of 'Cognitive Dissonance in Cybersecurity – A Review and Research Agenda'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver